CVE-2026-107297: fallo de gravedad media en mcollina msgpack5
msgpack5: Quadratic parsing in the streaming decoder
Publicada el
10Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 5.9
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
msgpack5 is a msgpack v5 implementation for node.js and the browser. Prior to 6.1.0, the streaming decoder reparses an incomplete array or map from the beginning whenever another chunk arrives. A remote peer can split one valid MessagePack container across many small chunks, causing completed elements to be decoded repeatedly, producing quadratic CPU use and blocking the event loop. This issue is fixed in version 6.1.0.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
mcollina · msgpack5CVEs relacionadas — mcollina msgpack5
En el mismo producto, de las más peligrosas a las menos.
CVE-2021-21368MEDIUMPrototype poisoningEPSS 1.6%CVE-2026-107302HIGHmsgpack5: Truncated map32 headers throw an unexpected errorEPSS —CVE-2026-107301MEDIUMmsgpack5: Partial options disable prototype protectionEPSS —CVE-2026-107300HIGHmsgpack5: Many buffered values can exhaust the streaming decoder stackEPSS —CVE-2026-107299MEDIUMmsgpack5: Reserved byte can cause unbounded stream bufferingEPSS —CVE-2026-107298MEDIUMmsgpack5: Deeply nested input can exhaust the decoder stackEPSS —